issues with secondary VMX execution controls
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Ubuntu Cloud Archive |
Fix Released
|
Undecided
|
Unassigned | ||
qemu (Ubuntu) |
Fix Released
|
High
|
Unassigned | ||
Focal |
Fix Released
|
High
|
Unassigned |
Bug Description
[Impact]
In qemu 4.2 was a change [1] meant to improve the handling of MSRs vs CPUID.
It was later identified [2] as an issue and fixed.
This has to be backported to Focal to resolve that issue on several platforms.
An example where this occurs is:
- Azure instances with nested virt
- GCP instances with nested virt
We have seen a bunch of qemu named CPU types that can expose similar behavior when used on chips that pretend to be of some type e.g. Skylake but miss some of their features to be settable.
It isn't entirely sure thou that this will be fixed by the same - yet worth to mention.
The impact is that qemu 4.2 as in Ubuntu 20.04 doesn't work on those platforms bailing out.
[1]: https:/
[2]: https:/
[Test Case]
* Get a GCP or Azure instance with nested virtualization enabled
* Spawn a KVM guest on it e.g. by using uvtool-libvirt using a named type
matching the cpu
e.g. if the host reports as skylake use such a type.
You can use `virsh domcapabilities` to check what the host is
detected as.
[Regression Potential]
* It is a bit hard to guess, but it should not make things worse. But if I'd expect one then the
VMX subfeatures could change on cases not intended to. Yet we should have one of two cases:
a) the common one is that the host can set this and has done so, it will continue as before
b) host was unable to set these and failed, this should now work with the fix in place
Both seem ok to me.
[Other Info]
* there might be a local (non cloud) way to reproduce but I don't know it yet
Related branches
- Rafael David Tinoco (community): Approve
- Canonical Server packageset reviewers: Pending requested
- Canonical Server: Pending requested
-
Diff: 183 lines (+155/-0)4 files modifieddebian/changelog (+9/-0)
debian/patches/lp-1882774-target-i386-do-not-set-unsupported-VMX-secondary-exe.patch (+103/-0)
debian/patches/series (+2/-0)
debian/patches/ubuntu/lp-1878973-fix-assert-regression.patch (+41/-0)
description: | updated |
Test fix started to build in PPA (for Focal): /launchpad. net/~ci- train-ppa- service/ +archive/ ubuntu/ 4081/
https:/
It would be great if one with GCP or Azure instances affected could give this a try.